SlideShare a Scribd company logo
Open Science & GDPR
Basic Concepts and Cases
Dr. Prodromos Tsiavos
Senior Legal & Policy Adviser
ARC/ ΟpenAIRE
https://www.athena-innovation.gr/ptsiavos@athenarc.gr
Open Science and GDPR
1. What is GDPR
2. Key DP structure
3. The setting
4. How is scientific research defined
5. Purpose
6. Legal Basis
7. Exercising data subject rights
8. Cases
What is GDPR?
Regulation (EU) 2016/679 of the European Parliament and of the
Council of 27 April 2016 on the protection of natural persons with
regard to the processing of personal data and on the free movement of
such data, and repealing Directive 95/46/EC (General Data Protection
Regulation)
1
Key DP structure
Personal Data
Type of processing
Purpose
Legal Basis
Be careful with
special categories
(sensitive) of
personal data
Make sure that the
legal basis covers
purpose and
personal data
2
The setting
Research within an RPO: check legal and ethics framework
EU or other collaborative projects - check WPs re who is processing what and
why:
Ethics and Data Protection Requirements (at the point/ WP of processing)
National Law
3rd countries
Call conditions (e.g. ethics report/ DPIA)
Tenders
Are you a data processor or (co)controller)?
Who is the DPO in a project (check the Consortium and Grant Agreement)?
3
How is scientific research defined
Sources:
- Recitals: 26, 33, 50, 52, 53, 62, 65, 113, 156, 157, 159, 160, 161, 162
- Relevant articles: 5(1)(b), (e), 89 (1), (2), (3), 9(j), 14(5)(b), 17(3)(d), 21(6).
Most important article:
- Art. 89
4
Defining Scientific Research I: Definitions
• It falls under the broader public interest legal basis (though this is not the
only possible legal basis)
• Could be a form of further processing (e.g. when obtaining data from a
public source or e.g. the government)
• Need to be subjected to appropriate safeguards
• Technical and organizational measures are in place
• Focus on data minimization (use only necessary data)
• Means: pseudonymization (without affecting research objectives)
Defining Scientific Research II: Special Categories
• In relation to special categories of data (art.9), the processing:
• shall be proportionate to the aim pursued
• needs to respect the right to data protection
• needs to provide suitable and specific measures to safeguard the
fundamental rights and interests of the data subject
The purpose
Possible purposes:
Overall: scientific research (art. 89 GDPR)
Specific type of research
Further use/ exploitation
What happens when the purpose changes over time?
Legal basis? [e.g. from public task to consent / collection by a public hospital – secondary use
by researchers)
Am I covered by the legal basis?
5
Legal Basis
Mostly forms of public interest (needs to be specifically documented per
institution and research project)
Contract (tender)
Consent (specific research)
Could change from collection, to retaining to sharing. There always needs to be
one covering the purpose of processing.
6
• Vital Interest
• Public Interest
• Legal Obligation
• Contract
• Consent
• Legitimate Interest
No discretion
discretion
Decision: both parties
Decision: data controller
Trace the life cycle
Follow the data (use the DMP as your backbone)
Different types of data processing may have different purposes and legal bases
Always stay within the legal basis
Data management plan
(processing/ purposes/ legal basis)
Data collection
- From the data
subject
- From 3rd party
- From publicly
available sources
Data Management
- Read
- Write (update/
improve/ enrich)
- Preservation
- Erasure
- Access
Data Sharing
- 3rd Parties
- Data processor
- Further use
- Subject
- Publishing
Purpose Α
Public Hospital
Public Interest A
Purpose C
Research Performing
Organisation
Legal Obligation
Purpose D
Research Performing
Organisation
Consent
Purpose Β
Research Performing
Organisation
Public Interest B
Exercising data subject rights
Limitation of rights of the data subject (arts. 14(5)/17(3)/ 21(6) GDPR))
Scientific research/ statistical purposes/ archiving
Public interest
Technical and organizational measures (mostly pseudonymization)
Condition: “it is likely to render impossible or seriously impair the achievement of
the objectives of that processing”
Notices (proactive data subject information)
7
Limitations to data subject’s rights:
(I) information
• Information to be provided where personal data have not been obtained
from the data subject (art. 14(5)(b)
• Researchers are exempt when:
• The provision of such information proves impossible or would involve a
disproportionate effort
• Such obligations would render impossible or seriously impair
achievement of the objectives of scientific research
• The controller takes appropriate measures to protect the data subject’s
legitimate interests
Limitations to data subject’s rights:
(II) erasure
• Right to erasure (‘right to be forgotten’) (art. 17(3)(d)
• Researchers are exempt when:
• Such obligations would render impossible or seriously impair
achievement of the objectives of scientific research
Limitations to data subject’s rights:
(III) objection
• Right to object (art. 21(6)
• Researchers are exempt when:
• the processing is necessary for the performance of a task carried out
for reasons of public interest.
Limitations to data subject’s rights:
(IV) Member States Derogations
• Member State derogations in relation to data-subject rights:
• Right of access by the data subject (art.15)
• Right to rectification (art.16)
• Right to restriction of processing (art.18)
• Right to object (art.21)
Cases
• Harvesting personal data from publicly available sources
• Data sharing with 3rd countries (international collaborations) – model
licences
• Initial collection for legitimate interest – secondary research use –
notification process - objection process
• Balancing reuse of research data and the GDPR principles of accuracy and
data minimization
• Health data and GDPR protection
• Data Sharing Codes of Conduct
• GDPR application for small projects
8
Cases
• Harvesting personal data from publicly available sources
• Check the original purpose of processing
• Check the original legal basis for processing
• It is a form of allowed further processing (art.5(b))
• Need to provide the following information to the data subject (art.14(1),(2)):
1. the identity and the contact details of the controller and, where applicable, of the controller's
representative
2. the contact details of the data protection officer, where applicable;
3. the purposes of the processing for which the personal data are intended as well as the legal
basis for the processing;
4. The categories of personal data concerned;
5. The recipients or categories of recipients of the personal data, if any;
6. When there is data transfer to 3rd countries, reference to the appropriate or suitable
safeguards and the means to obtain a copy of them or where they have been made available.
7. from which source the personal data originate, and if applicable, whether it came from
publicly accessible sources;
8a
Cases
• Conditions for further processing (arts.6(4)) + 13(3) + 14(4) + 89(1)):
1. Legal basis Consent; or
2. Legal obligations (by Member States); or
3. There is a new legal basis; or
4. Examine whether further processing is compatible with the purpose for which the personal
data were original collected:
1. What is the link between original and further processing
2. Context
3. If special categories exist and how they are protected
4. Consequences for the data subjects
5. Safeguards (e.g. encryption and pseudonymization)
5. When information is collected by the data-subject or third party, inform the data subject
regarding the further processing (prior to it) and any other relevant information (art.13(3) and
art.14(4))
6. Pseudonymize (if it is for research) art. 89(1)
8b
Cases
Transfers to 3rd countries
• Items:
• Conditions (contract or legal act) art.28
• Notifications and notices (data subject rights information – access ) (arts.13(1)(f), 14(1)(f),
15(1), (2))
• Keep records (art.30)
• Use of Codes of Conduct (art.40)
• Explore certification schemes, seals and marks (art.42(2))
• See entire Chapter V (arts.44-50)
• Adequacy decision
• Appropriate Safeguards
• Binding corporate rules
• Authorization by Union Law
• See EC Standard Contractual Clauses (SCC)
• Standard contractual clauses for data transfers between EU and non-EU countries.
8c
Cases
Initial collection for legitimate interest – secondary research use – notification process -
objection process
• Form of further processing
• Need to notify the data subject
• Include all notification principles of art.14
• There needs to be a clear opt-out/ objection process in the notification document:
• URL for automated opt-out
• At least email
• Always documented and confirmed
8d
Cases
Further processing and accuracy – minimization
• Adhere to all conditions of further processing
• Remain accurate through notices and notification
• Use only what is needed for the research purpose
• Erase data once the required processing is over (or retain data under archiving purposes)
8e
Cases
Health data and GDPR
- Special category of data (art.9)
- Form of Further Processing
- Emphasis on the legal basis
8f
Cases
Data Sharing CoCs
- ICO (UK)
[https://ico.org.uk/media/for-
organisations/documents/1068/data_sharing_code_of_practice.pdf]
- OECD
[http://www.oecd.org/gov/ethics/ethicscodesandcodesofconductinoecdcountries.htm]
8g
Cases
Personal data for small projects (excel rules…)
- Specify your research purpose and define data range
- Specify and document legal basis
- Manage and document consent
- Use DMP as your backbone
- Consult with your Ethics Committee and DPO
8h
q
a
ptsiavos@athenarc.gr

More Related Content

What's hot

GDPR - Thoughts on the EU Data Protection Regulation, Research and Libraries
GDPR - Thoughts on the EU Data Protection Regulation, Research and LibrariesGDPR - Thoughts on the EU Data Protection Regulation, Research and Libraries
GDPR - Thoughts on the EU Data Protection Regulation, Research and Libraries
LIBER Europe
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Financial Poise
 
Open if Possible, Protected if Needed: Services and tools for the sharing of...
Open if Possible, Protected if Needed:  Services and tools for the sharing of...Open if Possible, Protected if Needed:  Services and tools for the sharing of...
Open if Possible, Protected if Needed: Services and tools for the sharing of...
OpenAIRE
 
The Open Research Data Pilot: Personal Data and PSI Rules, Andreas Wiebe and ...
The Open Research Data Pilot: Personal Data and PSI Rules, Andreas Wiebe and ...The Open Research Data Pilot: Personal Data and PSI Rules, Andreas Wiebe and ...
The Open Research Data Pilot: Personal Data and PSI Rules, Andreas Wiebe and ...
OpenAIRE
 
Paperless Lab Academy 'legal aspects of big data analytics'
Paperless Lab Academy 'legal aspects of big data analytics' Paperless Lab Academy 'legal aspects of big data analytics'
Paperless Lab Academy 'legal aspects of big data analytics'
Axon Lawyers
 
The Right To Be Forgotten in the Google Spain Case (case C-131/12): A Clear V...
The Right To Be Forgotten in the Google Spain Case (case C-131/12): A Clear V...The Right To Be Forgotten in the Google Spain Case (case C-131/12): A Clear V...
The Right To Be Forgotten in the Google Spain Case (case C-131/12): A Clear V...ioannis iglezakis
 
UK & EU Freedom of Information & Data Protection: Continuity & Change
UK & EU Freedom of Information & Data Protection: Continuity & ChangeUK & EU Freedom of Information & Data Protection: Continuity & Change
UK & EU Freedom of Information & Data Protection: Continuity & Change
David Erdos
 
Brenda M. Simon, "The Pathologies of Biomedical ‘Data-Generating’ Patents: Le...
Brenda M. Simon, "The Pathologies of Biomedical ‘Data-Generating’ Patents: Le...Brenda M. Simon, "The Pathologies of Biomedical ‘Data-Generating’ Patents: Le...
Brenda M. Simon, "The Pathologies of Biomedical ‘Data-Generating’ Patents: Le...
The Petrie-Flom Center for Health Law Policy, Biotechnology, and Bioethics
 
The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...
The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...
The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...Kinfe Micheal Yilma
 
The interface between data protection and ip law
The interface between data protection and ip lawThe interface between data protection and ip law
The interface between data protection and ip law
Francesco Banterle
 
Privacy and Data Protection in Research
Privacy and Data Protection in ResearchPrivacy and Data Protection in Research
Privacy and Data Protection in Research
Marlon Domingus
 
The Privacy Advantage 2016 - Ruth Boardman
The Privacy Advantage 2016 - Ruth BoardmanThe Privacy Advantage 2016 - Ruth Boardman
The Privacy Advantage 2016 - Ruth Boardman
Krowdthink
 
Data Protection Forum meetup 23052017
Data Protection Forum meetup   23052017 Data Protection Forum meetup   23052017
Data Protection Forum meetup 23052017
John M Walsh
 
Operations network - consent under gdpr 24.01.2018
Operations network - consent under gdpr 24.01.2018Operations network - consent under gdpr 24.01.2018
Operations network - consent under gdpr 24.01.2018
MRS
 
Data Analytics and the Legal Landscape: Intellectual Property and Data Protec...
Data Analytics and the Legal Landscape: Intellectual Property and Data Protec...Data Analytics and the Legal Landscape: Intellectual Property and Data Protec...
Data Analytics and the Legal Landscape: Intellectual Property and Data Protec...
FutureTDM
 
Key principles for data protection & lawful protection in GDPR
Key principles for data protection & lawful protection in GDPRKey principles for data protection & lawful protection in GDPR
Key principles for data protection & lawful protection in GDPR
Dr. Marinos Papadopoulos
 
The Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiThe Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech Wiewiorowski
Krowdthink
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulations
Ulf Mattsson
 
Data, databases and what you can do with them
Data, databases and what you can do with themData, databases and what you can do with them
Data, databases and what you can do with them
Browne Jacobson LLP
 

What's hot (19)

GDPR - Thoughts on the EU Data Protection Regulation, Research and Libraries
GDPR - Thoughts on the EU Data Protection Regulation, Research and LibrariesGDPR - Thoughts on the EU Data Protection Regulation, Research and Libraries
GDPR - Thoughts on the EU Data Protection Regulation, Research and Libraries
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
Open if Possible, Protected if Needed: Services and tools for the sharing of...
Open if Possible, Protected if Needed:  Services and tools for the sharing of...Open if Possible, Protected if Needed:  Services and tools for the sharing of...
Open if Possible, Protected if Needed: Services and tools for the sharing of...
 
The Open Research Data Pilot: Personal Data and PSI Rules, Andreas Wiebe and ...
The Open Research Data Pilot: Personal Data and PSI Rules, Andreas Wiebe and ...The Open Research Data Pilot: Personal Data and PSI Rules, Andreas Wiebe and ...
The Open Research Data Pilot: Personal Data and PSI Rules, Andreas Wiebe and ...
 
Paperless Lab Academy 'legal aspects of big data analytics'
Paperless Lab Academy 'legal aspects of big data analytics' Paperless Lab Academy 'legal aspects of big data analytics'
Paperless Lab Academy 'legal aspects of big data analytics'
 
The Right To Be Forgotten in the Google Spain Case (case C-131/12): A Clear V...
The Right To Be Forgotten in the Google Spain Case (case C-131/12): A Clear V...The Right To Be Forgotten in the Google Spain Case (case C-131/12): A Clear V...
The Right To Be Forgotten in the Google Spain Case (case C-131/12): A Clear V...
 
UK & EU Freedom of Information & Data Protection: Continuity & Change
UK & EU Freedom of Information & Data Protection: Continuity & ChangeUK & EU Freedom of Information & Data Protection: Continuity & Change
UK & EU Freedom of Information & Data Protection: Continuity & Change
 
Brenda M. Simon, "The Pathologies of Biomedical ‘Data-Generating’ Patents: Le...
Brenda M. Simon, "The Pathologies of Biomedical ‘Data-Generating’ Patents: Le...Brenda M. Simon, "The Pathologies of Biomedical ‘Data-Generating’ Patents: Le...
Brenda M. Simon, "The Pathologies of Biomedical ‘Data-Generating’ Patents: Le...
 
The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...
The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...
The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...
 
The interface between data protection and ip law
The interface between data protection and ip lawThe interface between data protection and ip law
The interface between data protection and ip law
 
Privacy and Data Protection in Research
Privacy and Data Protection in ResearchPrivacy and Data Protection in Research
Privacy and Data Protection in Research
 
The Privacy Advantage 2016 - Ruth Boardman
The Privacy Advantage 2016 - Ruth BoardmanThe Privacy Advantage 2016 - Ruth Boardman
The Privacy Advantage 2016 - Ruth Boardman
 
Data Protection Forum meetup 23052017
Data Protection Forum meetup   23052017 Data Protection Forum meetup   23052017
Data Protection Forum meetup 23052017
 
Operations network - consent under gdpr 24.01.2018
Operations network - consent under gdpr 24.01.2018Operations network - consent under gdpr 24.01.2018
Operations network - consent under gdpr 24.01.2018
 
Data Analytics and the Legal Landscape: Intellectual Property and Data Protec...
Data Analytics and the Legal Landscape: Intellectual Property and Data Protec...Data Analytics and the Legal Landscape: Intellectual Property and Data Protec...
Data Analytics and the Legal Landscape: Intellectual Property and Data Protec...
 
Key principles for data protection & lawful protection in GDPR
Key principles for data protection & lawful protection in GDPRKey principles for data protection & lawful protection in GDPR
Key principles for data protection & lawful protection in GDPR
 
The Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiThe Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech Wiewiorowski
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulations
 
Data, databases and what you can do with them
Data, databases and what you can do with themData, databases and what you can do with them
Data, databases and what you can do with them
 

Similar to 20200504_Research Data & the GDPR: How Open is Open?

GDPR and Research Data Management
GDPR and Research Data ManagementGDPR and Research Data Management
GDPR and Research Data Management
London School of Hygiene and Tropical Medicine
 
Legal Guidelines regarding the Use of Electronic Patient Data. Do we need new...
Legal Guidelines regarding the Use of Electronic Patient Data. Do we need new...Legal Guidelines regarding the Use of Electronic Patient Data. Do we need new...
Legal Guidelines regarding the Use of Electronic Patient Data. Do we need new...
Plan de Calidad para el SNS
 
VIAF GDPR
VIAF GDPRVIAF GDPR
Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson LLP
 
Adjusting to the GDPR: The Impact on Data Scientists and Behavioral Researchers
Adjusting to the GDPR: The Impact on Data Scientists and Behavioral ResearchersAdjusting to the GDPR: The Impact on Data Scientists and Behavioral Researchers
Adjusting to the GDPR: The Impact on Data Scientists and Behavioral Researchers
Travis Greene
 
Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19
Niall Rooney
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)
Andrew Sharpe
 
Engage 2018: GDPR Three Days To Go
Engage 2018: GDPR Three Days To GoEngage 2018: GDPR Three Days To Go
Engage 2018: GDPR Three Days To Go
panagenda
 
GDPR for public sector DPO's seminar, April 2018, Manchester
GDPR for public sector DPO's seminar, April 2018, ManchesterGDPR for public sector DPO's seminar, April 2018, Manchester
GDPR for public sector DPO's seminar, April 2018, Manchester
Browne Jacobson LLP
 
GDPR 11/1/2017
GDPR 11/1/2017GDPR 11/1/2017
GDPR 11/1/2017
isc2-hellenic
 
GDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, NottinghamGDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, Nottingham
Browne Jacobson LLP
 
GDPR Overview
GDPR OverviewGDPR Overview
GDPR Overview
Trish McGinity, CCSK
 
DPOs in the public sector, May 2018, London
DPOs in the public sector, May 2018, LondonDPOs in the public sector, May 2018, London
DPOs in the public sector, May 2018, London
Browne Jacobson LLP
 
The Policy Framework: GDPR and all that
The Policy Framework: GDPR and all thatThe Policy Framework: GDPR and all that
The Policy Framework: GDPR and all that
EUDAT
 
DPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, BirminghamDPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, Birmingham
Browne Jacobson LLP
 
Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...
Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...
Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...
EUDAT
 
Data Protection & Risk Management
Data Protection & Risk Management Data Protection & Risk Management
Data Protection & Risk Management
Endcode_org
 
Are You GDPR Ready?
Are You GDPR Ready?Are You GDPR Ready?
Are You GDPR Ready?
NICSA
 
Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17
Michael Adamberry
 
GDPR - New European Union Legislation
GDPR - New European Union LegislationGDPR - New European Union Legislation
GDPR - New European Union Legislation
Tekwill
 

Similar to 20200504_Research Data & the GDPR: How Open is Open? (20)

GDPR and Research Data Management
GDPR and Research Data ManagementGDPR and Research Data Management
GDPR and Research Data Management
 
Legal Guidelines regarding the Use of Electronic Patient Data. Do we need new...
Legal Guidelines regarding the Use of Electronic Patient Data. Do we need new...Legal Guidelines regarding the Use of Electronic Patient Data. Do we need new...
Legal Guidelines regarding the Use of Electronic Patient Data. Do we need new...
 
VIAF GDPR
VIAF GDPRVIAF GDPR
VIAF GDPR
 
Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017
 
Adjusting to the GDPR: The Impact on Data Scientists and Behavioral Researchers
Adjusting to the GDPR: The Impact on Data Scientists and Behavioral ResearchersAdjusting to the GDPR: The Impact on Data Scientists and Behavioral Researchers
Adjusting to the GDPR: The Impact on Data Scientists and Behavioral Researchers
 
Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)
 
Engage 2018: GDPR Three Days To Go
Engage 2018: GDPR Three Days To GoEngage 2018: GDPR Three Days To Go
Engage 2018: GDPR Three Days To Go
 
GDPR for public sector DPO's seminar, April 2018, Manchester
GDPR for public sector DPO's seminar, April 2018, ManchesterGDPR for public sector DPO's seminar, April 2018, Manchester
GDPR for public sector DPO's seminar, April 2018, Manchester
 
GDPR 11/1/2017
GDPR 11/1/2017GDPR 11/1/2017
GDPR 11/1/2017
 
GDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, NottinghamGDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, Nottingham
 
GDPR Overview
GDPR OverviewGDPR Overview
GDPR Overview
 
DPOs in the public sector, May 2018, London
DPOs in the public sector, May 2018, LondonDPOs in the public sector, May 2018, London
DPOs in the public sector, May 2018, London
 
The Policy Framework: GDPR and all that
The Policy Framework: GDPR and all thatThe Policy Framework: GDPR and all that
The Policy Framework: GDPR and all that
 
DPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, BirminghamDPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, Birmingham
 
Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...
Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...
Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...
 
Data Protection & Risk Management
Data Protection & Risk Management Data Protection & Risk Management
Data Protection & Risk Management
 
Are You GDPR Ready?
Are You GDPR Ready?Are You GDPR Ready?
Are You GDPR Ready?
 
Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17
 
GDPR - New European Union Legislation
GDPR - New European Union LegislationGDPR - New European Union Legislation
GDPR - New European Union Legislation
 

More from OpenAIRE

10th OpenAIRE Content Providers Community Call
10th OpenAIRE Content Providers Community Call10th OpenAIRE Content Providers Community Call
10th OpenAIRE Content Providers Community Call
OpenAIRE
 
9th Content Providers Community Call\
9th Content Providers Community Call\9th Content Providers Community Call\
9th Content Providers Community Call\
OpenAIRE
 
OpenAIRE in the European Open Science Cloud (EOSC)
OpenAIRE in the European Open Science Cloud (EOSC)OpenAIRE in the European Open Science Cloud (EOSC)
OpenAIRE in the European Open Science Cloud (EOSC)
OpenAIRE
 
8th Content Providers Community Call
8th Content Providers Community Call8th Content Providers Community Call
8th Content Providers Community Call
OpenAIRE
 
7th Content Providers Community Call
7th Content Providers Community Call7th Content Providers Community Call
7th Content Providers Community Call
OpenAIRE
 
OpenAIRE PROVIDE Dashboard for Turkish repository managers
OpenAIRE PROVIDE Dashboard for Turkish repository managersOpenAIRE PROVIDE Dashboard for Turkish repository managers
OpenAIRE PROVIDE Dashboard for Turkish repository managers
OpenAIRE
 
What will it cost to manage and share my data?
What will it cost to manage and share my data?What will it cost to manage and share my data?
What will it cost to manage and share my data?
OpenAIRE
 
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 3)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 3)Open Research Gateway for the ELIXIR-GR Infrastructure (Part 3)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 3)
OpenAIRE
 
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 2)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 2)Open Research Gateway for the ELIXIR-GR Infrastructure (Part 2)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 2)
OpenAIRE
 
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 1)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 1)Open Research Gateway for the ELIXIR-GR Infrastructure (Part 1)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 1)
OpenAIRE
 
6th Content Providers Community Call
6th Content Providers Community Call6th Content Providers Community Call
6th Content Providers Community Call
OpenAIRE
 
COVID-19: Activities, tools, best practice and contact points in Greece
 COVID-19: Activities, tools, best practice and contact points in Greece COVID-19: Activities, tools, best practice and contact points in Greece
COVID-19: Activities, tools, best practice and contact points in Greece
OpenAIRE
 
5th Content Providers Community Call
5th Content Providers Community Call5th Content Providers Community Call
5th Content Providers Community Call
OpenAIRE
 
4th Content Providers Community Call
4th Content Providers Community Call4th Content Providers Community Call
4th Content Providers Community Call
OpenAIRE
 
3rd Content Providers Community Call
3rd Content Providers Community Call3rd Content Providers Community Call
3rd Content Providers Community Call
OpenAIRE
 
2nd Content Providers Community Call
2nd Content Providers Community Call2nd Content Providers Community Call
2nd Content Providers Community Call
OpenAIRE
 
1st Content Providers Community Call
1st Content Providers Community Call1st Content Providers Community Call
1st Content Providers Community Call
OpenAIRE
 
20200130_Mannocci_OpenAIRE_ResearchGraph
20200130_Mannocci_OpenAIRE_ResearchGraph20200130_Mannocci_OpenAIRE_ResearchGraph
20200130_Mannocci_OpenAIRE_ResearchGraph
OpenAIRE
 
IPR and Exploitation
IPR and Exploitation IPR and Exploitation
IPR and Exploitation
OpenAIRE
 
Eosc_OpenAIRE_onboarding_v2
Eosc_OpenAIRE_onboarding_v2Eosc_OpenAIRE_onboarding_v2
Eosc_OpenAIRE_onboarding_v2
OpenAIRE
 

More from OpenAIRE (20)

10th OpenAIRE Content Providers Community Call
10th OpenAIRE Content Providers Community Call10th OpenAIRE Content Providers Community Call
10th OpenAIRE Content Providers Community Call
 
9th Content Providers Community Call\
9th Content Providers Community Call\9th Content Providers Community Call\
9th Content Providers Community Call\
 
OpenAIRE in the European Open Science Cloud (EOSC)
OpenAIRE in the European Open Science Cloud (EOSC)OpenAIRE in the European Open Science Cloud (EOSC)
OpenAIRE in the European Open Science Cloud (EOSC)
 
8th Content Providers Community Call
8th Content Providers Community Call8th Content Providers Community Call
8th Content Providers Community Call
 
7th Content Providers Community Call
7th Content Providers Community Call7th Content Providers Community Call
7th Content Providers Community Call
 
OpenAIRE PROVIDE Dashboard for Turkish repository managers
OpenAIRE PROVIDE Dashboard for Turkish repository managersOpenAIRE PROVIDE Dashboard for Turkish repository managers
OpenAIRE PROVIDE Dashboard for Turkish repository managers
 
What will it cost to manage and share my data?
What will it cost to manage and share my data?What will it cost to manage and share my data?
What will it cost to manage and share my data?
 
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 3)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 3)Open Research Gateway for the ELIXIR-GR Infrastructure (Part 3)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 3)
 
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 2)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 2)Open Research Gateway for the ELIXIR-GR Infrastructure (Part 2)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 2)
 
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 1)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 1)Open Research Gateway for the ELIXIR-GR Infrastructure (Part 1)
Open Research Gateway for the ELIXIR-GR Infrastructure (Part 1)
 
6th Content Providers Community Call
6th Content Providers Community Call6th Content Providers Community Call
6th Content Providers Community Call
 
COVID-19: Activities, tools, best practice and contact points in Greece
 COVID-19: Activities, tools, best practice and contact points in Greece COVID-19: Activities, tools, best practice and contact points in Greece
COVID-19: Activities, tools, best practice and contact points in Greece
 
5th Content Providers Community Call
5th Content Providers Community Call5th Content Providers Community Call
5th Content Providers Community Call
 
4th Content Providers Community Call
4th Content Providers Community Call4th Content Providers Community Call
4th Content Providers Community Call
 
3rd Content Providers Community Call
3rd Content Providers Community Call3rd Content Providers Community Call
3rd Content Providers Community Call
 
2nd Content Providers Community Call
2nd Content Providers Community Call2nd Content Providers Community Call
2nd Content Providers Community Call
 
1st Content Providers Community Call
1st Content Providers Community Call1st Content Providers Community Call
1st Content Providers Community Call
 
20200130_Mannocci_OpenAIRE_ResearchGraph
20200130_Mannocci_OpenAIRE_ResearchGraph20200130_Mannocci_OpenAIRE_ResearchGraph
20200130_Mannocci_OpenAIRE_ResearchGraph
 
IPR and Exploitation
IPR and Exploitation IPR and Exploitation
IPR and Exploitation
 
Eosc_OpenAIRE_onboarding_v2
Eosc_OpenAIRE_onboarding_v2Eosc_OpenAIRE_onboarding_v2
Eosc_OpenAIRE_onboarding_v2
 

Recently uploaded

Predicting property prices with machine learning algorithms.pdf
Predicting property prices with machine learning algorithms.pdfPredicting property prices with machine learning algorithms.pdf
Predicting property prices with machine learning algorithms.pdf
binhminhvu04
 
extra-chromosomal-inheritance[1].pptx.pdfpdf
extra-chromosomal-inheritance[1].pptx.pdfpdfextra-chromosomal-inheritance[1].pptx.pdfpdf
extra-chromosomal-inheritance[1].pptx.pdfpdf
DiyaBiswas10
 
Structural Classification Of Protein (SCOP)
Structural Classification Of Protein  (SCOP)Structural Classification Of Protein  (SCOP)
Structural Classification Of Protein (SCOP)
aishnasrivastava
 
ESR_factors_affect-clinic significance-Pathysiology.pptx
ESR_factors_affect-clinic significance-Pathysiology.pptxESR_factors_affect-clinic significance-Pathysiology.pptx
ESR_factors_affect-clinic significance-Pathysiology.pptx
muralinath2
 
general properties of oerganologametal.ppt
general properties of oerganologametal.pptgeneral properties of oerganologametal.ppt
general properties of oerganologametal.ppt
IqrimaNabilatulhusni
 
(May 29th, 2024) Advancements in Intravital Microscopy- Insights for Preclini...
(May 29th, 2024) Advancements in Intravital Microscopy- Insights for Preclini...(May 29th, 2024) Advancements in Intravital Microscopy- Insights for Preclini...
(May 29th, 2024) Advancements in Intravital Microscopy- Insights for Preclini...
Scintica Instrumentation
 
Orion Air Quality Monitoring Systems - CWS
Orion Air Quality Monitoring Systems - CWSOrion Air Quality Monitoring Systems - CWS
Orion Air Quality Monitoring Systems - CWS
Columbia Weather Systems
 
filosofia boliviana introducción jsjdjd.pptx
filosofia boliviana introducción jsjdjd.pptxfilosofia boliviana introducción jsjdjd.pptx
filosofia boliviana introducción jsjdjd.pptx
IvanMallco1
 
Comparative structure of adrenal gland in vertebrates
Comparative structure of adrenal gland in vertebratesComparative structure of adrenal gland in vertebrates
Comparative structure of adrenal gland in vertebrates
sachin783648
 
erythropoiesis-I_mechanism& clinical significance.pptx
erythropoiesis-I_mechanism& clinical significance.pptxerythropoiesis-I_mechanism& clinical significance.pptx
erythropoiesis-I_mechanism& clinical significance.pptx
muralinath2
 
Seminar of U.V. Spectroscopy by SAMIR PANDA
 Seminar of U.V. Spectroscopy by SAMIR PANDA Seminar of U.V. Spectroscopy by SAMIR PANDA
Seminar of U.V. Spectroscopy by SAMIR PANDA
SAMIR PANDA
 
insect morphology and physiology of insect
insect morphology and physiology of insectinsect morphology and physiology of insect
insect morphology and physiology of insect
anitaento25
 
In silico drugs analogue design: novobiocin analogues.pptx
In silico drugs analogue design: novobiocin analogues.pptxIn silico drugs analogue design: novobiocin analogues.pptx
In silico drugs analogue design: novobiocin analogues.pptx
AlaminAfendy1
 
Anemia_ different types_causes_ conditions
Anemia_ different types_causes_ conditionsAnemia_ different types_causes_ conditions
Anemia_ different types_causes_ conditions
muralinath2
 
Unveiling the Energy Potential of Marshmallow Deposits.pdf
Unveiling the Energy Potential of Marshmallow Deposits.pdfUnveiling the Energy Potential of Marshmallow Deposits.pdf
Unveiling the Energy Potential of Marshmallow Deposits.pdf
Erdal Coalmaker
 
Earliest Galaxies in the JADES Origins Field: Luminosity Function and Cosmic ...
Earliest Galaxies in the JADES Origins Field: Luminosity Function and Cosmic ...Earliest Galaxies in the JADES Origins Field: Luminosity Function and Cosmic ...
Earliest Galaxies in the JADES Origins Field: Luminosity Function and Cosmic ...
Sérgio Sacani
 
The ASGCT Annual Meeting was packed with exciting progress in the field advan...
The ASGCT Annual Meeting was packed with exciting progress in the field advan...The ASGCT Annual Meeting was packed with exciting progress in the field advan...
The ASGCT Annual Meeting was packed with exciting progress in the field advan...
Health Advances
 
Richard's aventures in two entangled wonderlands
Richard's aventures in two entangled wonderlandsRichard's aventures in two entangled wonderlands
Richard's aventures in two entangled wonderlands
Richard Gill
 
Circulatory system_ Laplace law. Ohms law.reynaults law,baro-chemo-receptors-...
Circulatory system_ Laplace law. Ohms law.reynaults law,baro-chemo-receptors-...Circulatory system_ Laplace law. Ohms law.reynaults law,baro-chemo-receptors-...
Circulatory system_ Laplace law. Ohms law.reynaults law,baro-chemo-receptors-...
muralinath2
 
platelets_clotting_biogenesis.clot retractionpptx
platelets_clotting_biogenesis.clot retractionpptxplatelets_clotting_biogenesis.clot retractionpptx
platelets_clotting_biogenesis.clot retractionpptx
muralinath2
 

Recently uploaded (20)

Predicting property prices with machine learning algorithms.pdf
Predicting property prices with machine learning algorithms.pdfPredicting property prices with machine learning algorithms.pdf
Predicting property prices with machine learning algorithms.pdf
 
extra-chromosomal-inheritance[1].pptx.pdfpdf
extra-chromosomal-inheritance[1].pptx.pdfpdfextra-chromosomal-inheritance[1].pptx.pdfpdf
extra-chromosomal-inheritance[1].pptx.pdfpdf
 
Structural Classification Of Protein (SCOP)
Structural Classification Of Protein  (SCOP)Structural Classification Of Protein  (SCOP)
Structural Classification Of Protein (SCOP)
 
ESR_factors_affect-clinic significance-Pathysiology.pptx
ESR_factors_affect-clinic significance-Pathysiology.pptxESR_factors_affect-clinic significance-Pathysiology.pptx
ESR_factors_affect-clinic significance-Pathysiology.pptx
 
general properties of oerganologametal.ppt
general properties of oerganologametal.pptgeneral properties of oerganologametal.ppt
general properties of oerganologametal.ppt
 
(May 29th, 2024) Advancements in Intravital Microscopy- Insights for Preclini...
(May 29th, 2024) Advancements in Intravital Microscopy- Insights for Preclini...(May 29th, 2024) Advancements in Intravital Microscopy- Insights for Preclini...
(May 29th, 2024) Advancements in Intravital Microscopy- Insights for Preclini...
 
Orion Air Quality Monitoring Systems - CWS
Orion Air Quality Monitoring Systems - CWSOrion Air Quality Monitoring Systems - CWS
Orion Air Quality Monitoring Systems - CWS
 
filosofia boliviana introducción jsjdjd.pptx
filosofia boliviana introducción jsjdjd.pptxfilosofia boliviana introducción jsjdjd.pptx
filosofia boliviana introducción jsjdjd.pptx
 
Comparative structure of adrenal gland in vertebrates
Comparative structure of adrenal gland in vertebratesComparative structure of adrenal gland in vertebrates
Comparative structure of adrenal gland in vertebrates
 
erythropoiesis-I_mechanism& clinical significance.pptx
erythropoiesis-I_mechanism& clinical significance.pptxerythropoiesis-I_mechanism& clinical significance.pptx
erythropoiesis-I_mechanism& clinical significance.pptx
 
Seminar of U.V. Spectroscopy by SAMIR PANDA
 Seminar of U.V. Spectroscopy by SAMIR PANDA Seminar of U.V. Spectroscopy by SAMIR PANDA
Seminar of U.V. Spectroscopy by SAMIR PANDA
 
insect morphology and physiology of insect
insect morphology and physiology of insectinsect morphology and physiology of insect
insect morphology and physiology of insect
 
In silico drugs analogue design: novobiocin analogues.pptx
In silico drugs analogue design: novobiocin analogues.pptxIn silico drugs analogue design: novobiocin analogues.pptx
In silico drugs analogue design: novobiocin analogues.pptx
 
Anemia_ different types_causes_ conditions
Anemia_ different types_causes_ conditionsAnemia_ different types_causes_ conditions
Anemia_ different types_causes_ conditions
 
Unveiling the Energy Potential of Marshmallow Deposits.pdf
Unveiling the Energy Potential of Marshmallow Deposits.pdfUnveiling the Energy Potential of Marshmallow Deposits.pdf
Unveiling the Energy Potential of Marshmallow Deposits.pdf
 
Earliest Galaxies in the JADES Origins Field: Luminosity Function and Cosmic ...
Earliest Galaxies in the JADES Origins Field: Luminosity Function and Cosmic ...Earliest Galaxies in the JADES Origins Field: Luminosity Function and Cosmic ...
Earliest Galaxies in the JADES Origins Field: Luminosity Function and Cosmic ...
 
The ASGCT Annual Meeting was packed with exciting progress in the field advan...
The ASGCT Annual Meeting was packed with exciting progress in the field advan...The ASGCT Annual Meeting was packed with exciting progress in the field advan...
The ASGCT Annual Meeting was packed with exciting progress in the field advan...
 
Richard's aventures in two entangled wonderlands
Richard's aventures in two entangled wonderlandsRichard's aventures in two entangled wonderlands
Richard's aventures in two entangled wonderlands
 
Circulatory system_ Laplace law. Ohms law.reynaults law,baro-chemo-receptors-...
Circulatory system_ Laplace law. Ohms law.reynaults law,baro-chemo-receptors-...Circulatory system_ Laplace law. Ohms law.reynaults law,baro-chemo-receptors-...
Circulatory system_ Laplace law. Ohms law.reynaults law,baro-chemo-receptors-...
 
platelets_clotting_biogenesis.clot retractionpptx
platelets_clotting_biogenesis.clot retractionpptxplatelets_clotting_biogenesis.clot retractionpptx
platelets_clotting_biogenesis.clot retractionpptx
 

20200504_Research Data & the GDPR: How Open is Open?

  • 1. Open Science & GDPR Basic Concepts and Cases Dr. Prodromos Tsiavos Senior Legal & Policy Adviser ARC/ ΟpenAIRE https://www.athena-innovation.gr/ptsiavos@athenarc.gr
  • 2. Open Science and GDPR 1. What is GDPR 2. Key DP structure 3. The setting 4. How is scientific research defined 5. Purpose 6. Legal Basis 7. Exercising data subject rights 8. Cases
  • 3. What is GDPR? Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) 1
  • 4. Key DP structure Personal Data Type of processing Purpose Legal Basis Be careful with special categories (sensitive) of personal data Make sure that the legal basis covers purpose and personal data 2
  • 5. The setting Research within an RPO: check legal and ethics framework EU or other collaborative projects - check WPs re who is processing what and why: Ethics and Data Protection Requirements (at the point/ WP of processing) National Law 3rd countries Call conditions (e.g. ethics report/ DPIA) Tenders Are you a data processor or (co)controller)? Who is the DPO in a project (check the Consortium and Grant Agreement)? 3
  • 6. How is scientific research defined Sources: - Recitals: 26, 33, 50, 52, 53, 62, 65, 113, 156, 157, 159, 160, 161, 162 - Relevant articles: 5(1)(b), (e), 89 (1), (2), (3), 9(j), 14(5)(b), 17(3)(d), 21(6). Most important article: - Art. 89 4
  • 7. Defining Scientific Research I: Definitions • It falls under the broader public interest legal basis (though this is not the only possible legal basis) • Could be a form of further processing (e.g. when obtaining data from a public source or e.g. the government) • Need to be subjected to appropriate safeguards • Technical and organizational measures are in place • Focus on data minimization (use only necessary data) • Means: pseudonymization (without affecting research objectives)
  • 8. Defining Scientific Research II: Special Categories • In relation to special categories of data (art.9), the processing: • shall be proportionate to the aim pursued • needs to respect the right to data protection • needs to provide suitable and specific measures to safeguard the fundamental rights and interests of the data subject
  • 9. The purpose Possible purposes: Overall: scientific research (art. 89 GDPR) Specific type of research Further use/ exploitation What happens when the purpose changes over time? Legal basis? [e.g. from public task to consent / collection by a public hospital – secondary use by researchers) Am I covered by the legal basis? 5
  • 10. Legal Basis Mostly forms of public interest (needs to be specifically documented per institution and research project) Contract (tender) Consent (specific research) Could change from collection, to retaining to sharing. There always needs to be one covering the purpose of processing. 6
  • 11. • Vital Interest • Public Interest • Legal Obligation • Contract • Consent • Legitimate Interest No discretion discretion Decision: both parties Decision: data controller
  • 12. Trace the life cycle Follow the data (use the DMP as your backbone) Different types of data processing may have different purposes and legal bases Always stay within the legal basis
  • 13. Data management plan (processing/ purposes/ legal basis) Data collection - From the data subject - From 3rd party - From publicly available sources Data Management - Read - Write (update/ improve/ enrich) - Preservation - Erasure - Access Data Sharing - 3rd Parties - Data processor - Further use - Subject - Publishing Purpose Α Public Hospital Public Interest A Purpose C Research Performing Organisation Legal Obligation Purpose D Research Performing Organisation Consent Purpose Β Research Performing Organisation Public Interest B
  • 14. Exercising data subject rights Limitation of rights of the data subject (arts. 14(5)/17(3)/ 21(6) GDPR)) Scientific research/ statistical purposes/ archiving Public interest Technical and organizational measures (mostly pseudonymization) Condition: “it is likely to render impossible or seriously impair the achievement of the objectives of that processing” Notices (proactive data subject information) 7
  • 15. Limitations to data subject’s rights: (I) information • Information to be provided where personal data have not been obtained from the data subject (art. 14(5)(b) • Researchers are exempt when: • The provision of such information proves impossible or would involve a disproportionate effort • Such obligations would render impossible or seriously impair achievement of the objectives of scientific research • The controller takes appropriate measures to protect the data subject’s legitimate interests
  • 16. Limitations to data subject’s rights: (II) erasure • Right to erasure (‘right to be forgotten’) (art. 17(3)(d) • Researchers are exempt when: • Such obligations would render impossible or seriously impair achievement of the objectives of scientific research
  • 17. Limitations to data subject’s rights: (III) objection • Right to object (art. 21(6) • Researchers are exempt when: • the processing is necessary for the performance of a task carried out for reasons of public interest.
  • 18. Limitations to data subject’s rights: (IV) Member States Derogations • Member State derogations in relation to data-subject rights: • Right of access by the data subject (art.15) • Right to rectification (art.16) • Right to restriction of processing (art.18) • Right to object (art.21)
  • 19. Cases • Harvesting personal data from publicly available sources • Data sharing with 3rd countries (international collaborations) – model licences • Initial collection for legitimate interest – secondary research use – notification process - objection process • Balancing reuse of research data and the GDPR principles of accuracy and data minimization • Health data and GDPR protection • Data Sharing Codes of Conduct • GDPR application for small projects 8
  • 20. Cases • Harvesting personal data from publicly available sources • Check the original purpose of processing • Check the original legal basis for processing • It is a form of allowed further processing (art.5(b)) • Need to provide the following information to the data subject (art.14(1),(2)): 1. the identity and the contact details of the controller and, where applicable, of the controller's representative 2. the contact details of the data protection officer, where applicable; 3. the purposes of the processing for which the personal data are intended as well as the legal basis for the processing; 4. The categories of personal data concerned; 5. The recipients or categories of recipients of the personal data, if any; 6. When there is data transfer to 3rd countries, reference to the appropriate or suitable safeguards and the means to obtain a copy of them or where they have been made available. 7. from which source the personal data originate, and if applicable, whether it came from publicly accessible sources; 8a
  • 21. Cases • Conditions for further processing (arts.6(4)) + 13(3) + 14(4) + 89(1)): 1. Legal basis Consent; or 2. Legal obligations (by Member States); or 3. There is a new legal basis; or 4. Examine whether further processing is compatible with the purpose for which the personal data were original collected: 1. What is the link between original and further processing 2. Context 3. If special categories exist and how they are protected 4. Consequences for the data subjects 5. Safeguards (e.g. encryption and pseudonymization) 5. When information is collected by the data-subject or third party, inform the data subject regarding the further processing (prior to it) and any other relevant information (art.13(3) and art.14(4)) 6. Pseudonymize (if it is for research) art. 89(1) 8b
  • 22. Cases Transfers to 3rd countries • Items: • Conditions (contract or legal act) art.28 • Notifications and notices (data subject rights information – access ) (arts.13(1)(f), 14(1)(f), 15(1), (2)) • Keep records (art.30) • Use of Codes of Conduct (art.40) • Explore certification schemes, seals and marks (art.42(2)) • See entire Chapter V (arts.44-50) • Adequacy decision • Appropriate Safeguards • Binding corporate rules • Authorization by Union Law • See EC Standard Contractual Clauses (SCC) • Standard contractual clauses for data transfers between EU and non-EU countries. 8c
  • 23. Cases Initial collection for legitimate interest – secondary research use – notification process - objection process • Form of further processing • Need to notify the data subject • Include all notification principles of art.14 • There needs to be a clear opt-out/ objection process in the notification document: • URL for automated opt-out • At least email • Always documented and confirmed 8d
  • 24. Cases Further processing and accuracy – minimization • Adhere to all conditions of further processing • Remain accurate through notices and notification • Use only what is needed for the research purpose • Erase data once the required processing is over (or retain data under archiving purposes) 8e
  • 25. Cases Health data and GDPR - Special category of data (art.9) - Form of Further Processing - Emphasis on the legal basis 8f
  • 26. Cases Data Sharing CoCs - ICO (UK) [https://ico.org.uk/media/for- organisations/documents/1068/data_sharing_code_of_practice.pdf] - OECD [http://www.oecd.org/gov/ethics/ethicscodesandcodesofconductinoecdcountries.htm] 8g
  • 27. Cases Personal data for small projects (excel rules…) - Specify your research purpose and define data range - Specify and document legal basis - Manage and document consent - Use DMP as your backbone - Consult with your Ethics Committee and DPO 8h